Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Mozilla Browser Postfix String Security Question

0 views
Skip to first unread message

Mark Hobley

unread,
Oct 2, 2010, 3:44:56 AM10/2/10
to
When browsing some websites, postfix information can be included in the url
that can be detected by the webserver. This is typically used for providing
information to the browser using the GET method of the CGI common gateway
interface.

http://stcanning-your-computerc.com/scn1/?id=%3DnQ3xTzuNDMyLjE1MC4yNTImcGlkPTM2NHMxJnRpbWU9MTI2MjkyNg0OaA%3DM

Is it possible that the string being passed from the browser could contain
information for another website, or any information taken from another
window that just happens to be open at the same time?

For example, If I have two browser windows open at the same time:

www.idonotwanttosharethislink.com

and www.wespyonyou.com//scn1/?id=%3DnQ3xTzuNDMyLjE1MC4yNTImcGlkPTM2NHMxJnRpbWU9MTI2MjkyNg0OaA%3DM

Is it possible that wespyonyou.com knows that you have visited or bookmarked
www.idonotwanttosharethislink.com, because this information is being encoded
into the into the postfix string by the browser?

Mark.

--
Mark Hobley
Linux User: #370818 http://markhobley.yi.org/

0 new messages